Processing of (personal) data by the entity in charge of the online application process
Privacy Notice for Applicants
According to the requirements of art. 13 GDPR related to the information obligations, this privacy notice provides you with information on OpenSynergy’s data processing activities regarding your application:
Data processing responsible in the frame of the application process is
OpenSynergy GmbH
Rotherstraße 20
10245 Berlin
Germany
E-Mail: datenschutz(at)opensynergy.com
Our data protection officer
If you have any questions about data protection at OpenSynergy, you are welcome to contact our data protection officer by e-mail to datenschutz(at)opensynergy.com. We expressly point out that if you use this e-mail address, the contents will not be viewed exclusively by our data protection officer. If you wish to exchange confidential information, we therefore ask that you first contact us via this e-mail address.
Type and purpose of the data processing
If we have received data from you, we will only process it for the purpose for which we have collected it.
These purposes are usually:
- the justification and the establishment of an employment relationship in the course of an application process
- the entry in our applicant pool in order to identify any possible vacancies of interest to you and eventually contact you again
With the reception and the processing of your application, we collect the following data:
- first and last name
- address
- telephone number
- job description
- email address
- further data you provide in your application materials
(CV, certificates, special categories of personal data e. g. information regarding severe disability)
If you provide us with additional personal data about yourself (e.g. a photo) that is not required, this is done on the basis of your voluntary decision.
Legal basis of the data processing
Legal basis for processing your application is art. 6 para. 1 sentence 1 lit. b GDPR. If your application is unsuccessful, your data will be processed in the applicant pool on the basis of your consent in accordance with art. 6 para. 1 lit. a GDPR. Please note that you can revoke this consent at any time with effect for the future by sending us an e-mail to datenschutz(at)opensynergy.com. The processing of special categories of personal data only to the extent necessary or where voluntarily provided is based on Art. 9 para. 1 lit. b GDPR in conjunction with Section 26(3) of the BDSG.
How long shall the data be stored?
- Employment: if we conclude an employment contract with you, we store the data we collect and the data you voluntarily provide for the duration of your employment relationship respectively for the legally required retention period.
- Rejection: if we reject your application, we will save your application data for a maximum of six months after your application has been rejected.
- Applicant pool: if you have given us your separate consent, we will store the data you have submitted with your application in our applicant pool for twelve months after the end of the application process to identify any other vacancies of interest to you and to contact you again if necessary.
- Reimbursement of expenses: if you have been invited to an in-person interview at our office, we reimburse you for appropriate and necessary travel expenses incurred. To do so, we process your bank account information (first name, last name and IBAN). The legal basis is Art. 6 para. 1 lit. b GDPR. The data is stored for the duration of the statutory accounting obligations in accordance with Section 147 para. 1, No. 2, 3 / No. 5 AO, unless they qualify as accounting documents within the meaning of Section 147 para. 1 No. 4 AO, in which case a retention period of 8 years applies.
To which recipients is the data passed on?
We use the technical support of the Software of Personio for our application process. Personio is provided to us by Personio SE & Co. KG, Seidlstraße 3, 80335 München, Germany (“Personio”). The data you submitted will be processed by Personio on our behalf for the purpose of carrying out and processing the application process. We have concluded a data processing agreement with Personio according to the requirements of art. 28 para. 3 GDPR.
To identify and defend against any export control related compliance risks, we check you for any incidents that could lead to a breach of legal requirements on our part when initiating an employment relationship. For compliance and export control screening, your full legal name is entered into export control screening websites for individuals provided by the European Union and in certain cases the one provided by the Office of Foreign Assets Control or any other applicable official sanction list relevant for your role. We are doing this to be informed in good time if there is a risk in the employment. The legal basis for this processing activity is Art. 6 para. 1 lit. f GDPR. Our legitimate interest here lies in minimizing risk by complying with legal prohibitions and avoiding sanctions. The data is not stored in the screening software solution for one time screening of applicants. Only where there is a verified “match” of your data with data of a sanctioned person, the screening result, including your data in anonymized form will be stored for a period of 10 years, starting at the end of the year of the screening, in accordance with Art. 6 para. 1 lit. f GDPR, for documentation and verification purposes in order to ward off any criminal prosecution of our company.
Visiting the site/Cookies
Access data is automatically collected from your web browser each time you access our website. Access data includes in particular:
- IP address of the requesting device
- date and time of access
- address of the web page accessed and the requested web page
- web browser you use and the operating system of your device
- online ID (e.g. device IDs, session IDs).
The processing of the access data is only collected for the purpose of enabling you to visit the website and to ensure the long-term functionality and security of our system. In this respect, legal basis for the data processing is art. 6 para. 1 lit. f GDPR. Our legitimate interest follows the aforementioned purposes. For data protection reasons, log files are only stored or analyzed temporarily.
When you visit and use our website, so-called “session cookies” are installed and stored on your computer. Cookies are small text files that are used to make the use of our services more user-friendly, more efficient and safe. They do not cause any damage to your computer and do not contain any viruses.
As a rule, session cookies are automatically deleted after your visit. You have the option of deactivating the storage of cookies by making appropriate settings in your browser. However, we would like to point out that you may in this case not access all functions of this website without restrictions. In this respect, the legal basis for the data processing is art. 6 para. 1 lit. f GDPR.
For more detailed information, please have a look at the cookies section in our privacy policy.
Online meetings via Microsoft Teams ("Teams")
For a first and/or consecutive interviews we may use Teams if it is preferable to a face-to-face meeting or an initial telephone call. Teams is a software of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA ("Microsoft"), available as desktop, web and mobile app. It is used by us in particular for conducting digital conferences with business partners and applicants.
Legal basis for data processing is our legitimate interest in the effective conduct of meetings in accordance with Art. 6 para. 1 lit. f GDPR. We are not responsible for further data processing on the product website of Teams, where the desktop software can be downloaded, and the web app can be used.
During a meeting the following data may be processed under certain circumstances:
· Information about the participant: if applicable, display name, first name, last name, telephone, e-mail address, password (encrypted for authentication), profile picture;
· Metadata: meeting topic and description, IP address, participant's phone number, type of device/software (Windows/Mac/Linux/Web/iOS/Android Phone/Windows Phone), time of participant´s last activity on teams, number of chat and channel messages, number of meetings attended, duration of time for audio, video, and screen sharing;
· When using chat or channel messages: text data for display and, if applicable, logging;
· For audio use: recording data of microphone;
· When using video: recording data of video camera;
· For phone usage: incoming and outgoing phone numbers, country name, start and end time, if applicable other connection data, such as the IP address of the device.
Prior to a meeting, you must register via our website or by e-mail. Your registration data will be processed by us. Before the meeting, you will receive a confirmation email with an invitation link or a calendar appointment.
In order to participate in a meeting, you must at least provide information about your name and - in case of telephone use - your telephone number, unless we make it possible to participate anonymously in meetings. In the latter case, we will inform you of this possibility of anonymous participation in the invitation. You can deactivate transmission via microphone and camera at any time via the corresponding settings. We will only record meetings or log text data with your consent and prior notification. Microsoft stores and uses the metadata to enable us to analyze and report on team usage.
Microsoft may obtain knowledge of the above-mentioned data in the course of processing orders in order to process them. All data traffic is encrypted (MTLS, TLS, or SRTP) and is generally performed at European servers. In case data are processed in the USA, we have agreed upon Standard Contractual Clauses with Microsoft as legal basis for data transfer and Microsoft has registered under Data Privacy Framework. Therefore, the transfer of personal data is based on the EU Commission's latest adequacy decision for data transfers to the USA. For more information, please find enclosed the Microsoft Privacy Policy.
You can find more information in the privacy policy from Microsoft.
Intra Group Data Processing and International Transfers
Depending on your profile and the position you are applying for, we may share your application data as described in Section 3 with colleagues at our subsidiary OpenSynergy, Inc., located in the United States. Where such transfers involve the transfer of personal data to a third country outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place in accordance with Article 46 GDPR. In particular, the transfer is based on the European Commission’s Standard Contractual Clauses (SCCs), as incorporated into an intra-group data transfer agreement. Where required, we also implement supplementary technical and organizational measures to ensure a level of data protection essentially equivalent to that guaranteed within the EEA.
Your rights
You have the right to request information about the processing of your personal data by us according to art. 15 GDPR. Furthermore, you have the right to rectification in accordance to art. 16 GDPR, the right to erasure under art. 17 GDPR, the right to restriction of processing under art. 18 GDPR, the right to notification under art. 19 and the right to data portability under art. 20 GDPR.
Also, you have the right according to art. 21 GDPR to object to the processing of your personal data, insofar as the processing of your personal data takes place in accordance with art. 6 para.1 lit. f) GDPR.
Insofar as the processing of your personal data takes place on the basis of your consent, you are entitled to revoke your consent to the processing of your personal data at any time in according to art. 7 para. 3 GDPR. Please note that the revocation will only take effect in the future.
Right to lodge a complaint
You have the right to file a complaint about personal data processing to the data protection supervisory authority responsible for us. You can assert this right with a supervisory authority in the Member State in which you are resident, your place of work or the place of the suspected infringement. In Berlin the competent supervisory authority is: Berlin Commissioner for Privacy and Freedom of Information, Alt-Moabit 59-61, 10555 Berlin.
Version, Sep. 2026